Citrix NetScaler SAML zero-day CVE-2026-88779 patched

Citrix NetScaler SAML zero-day CVE-2026-88779 patched

Citrix has shipped emergency fixes for CVE-2026-88779, a NetScaler vulnerability that attackers exploited as a zero-day before a patch existed. The company describes it as a denial-of-service bug. Researchers are now checking whether it can also be used to run code remotely.

The flaw is a memory buffer issue in NetScaler ADC and NetScaler Gateway appliances that use SAML authentication together with Gateway or AAA (authentication, authorization and auditing) functionality. Citrix rates it 8.7 on the CVSS scale. According to its advisory, it has been used in targeted attacks against unmitigated deployments.

"Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service," the company said in a blog post. It added that repeated triggering can keep the service unavailable, and that its analysis found an impact on availability but not on the integrity of customer data.

Which versions fix the flaw

Early on Sunday, Citrix released NetScaler ADC and NetScaler Gateway versions 14.1-73.41 and 13.1-64.28. FIPS deployments should move to 14.1-73.41 FIPS. NetScaler ADC FIPS and NDcPP customers on the 13.1 branch need 13.1-37.282.

Citrix is also offering Global Deny Lists that block known malicious IP addresses. However, it still tells customers to install the new updates as soon as possible.

Admins can check exposure by looking at the SAML configuration. An appliance is affected if it is set up as a SAML service provider (add authentication samlAction) or as a SAML identity provider (add authentication samlIdPProfile).

This means another round of upgrades for many teams. Organizations that recently patched the actively exploited flaws covered in the bulletin for CVE-2026-88771 through CVE-2026-88778 must upgrade again if their setup meets these conditions. Several of those earlier bugs drew heavy attention, including mass exploitation of CVE-2026-88771 and a zero-day linked to state hackers.

Reboots on freshly patched appliances

The problem first surfaced on Thursday. NetScaler administrators noticed that recently patched appliances were rebooting on their own.

On Reddit, one admin said multiple customers on NetScaler 14.1-73.37 were hit by repeated forced reboots, even though they had installed the latest updates available at the time. Others reported the same behavior, including on appliances rebuilt from fresh images. One thread described the nsaaad process crashing again and again until NetScaler's Pitboss process hit its restart limit and rebooted the device.

At first it was not clear whether vulnerability scanners were tripping a bug in new firmware or whether attackers were exploiting a new flaw.

One administrator examining 14.1-73.37 devices then found crafted authentication usernames containing shell commands. These commands pulled a payload from 213.209.159[.]55, saved it as /v and executed it. The requests came right before three confirmed nsaaad crash sequences on one appliance and targeted multiple SAML authentication factors. The admin noted that the logs showed attempted exploitation and matching crashes, but did not prove the commands actually ran.

On Friday, Citrix published a notice saying its teams were tracking a "newly observed issue" tied to SAML authentication in customer-managed NetScaler deployments. It confirmed the issue was separate from the previously disclosed vulnerabilities.

Honeypots point beyond denial-of-service

Security researcher Kevin Beaumont reported that his patched NetScaler 13.1 and 14.1 honeypots were crashing after requests from several source IP addresses. He called it potentially another "PitScaler" vulnerability.

He later found that one of the patched honeypots was running a downloaded malware payload. "So on one of the honeypots it's running a downloaded (malware) binary. Both were patched, so new vuln," Beaumont said. "It's being sprayed and prayed. One of the honeypots doesn't even have a valid SSL certificate as I let it expire."

Beaumont also pointed out that Citrix's wording, a "Memory overflow vulnerability leading to Denial of Service," echoes how CVE-2025-6543 was first described. That flaw was later shown to allow remote code execution.

watchTowr Labs said it has reproduced the vulnerability but has not shared technical details yet.

On Sunday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch (FCEB) agencies have until October 7 to mitigate it.

Our Take

For NetScaler customers, this is the third patch cycle in a short period, and it hit appliances that had already been updated. That suggests applying the latest build alone is not enough. Teams should also watch for unusual crashes and reboots, since admins spotted this attack through nsaaad and Pitboss behavior well before Citrix had a fix.

The gap between the vendor's "denial-of-service" label and what researchers observed deserves attention. Given the CVE-2025-6543 precedent and a honeypot running a downloaded binary, it would be prudent to treat CVE-2026-88779 as a potential code execution flaw. Affected organizations should also check SAML-enabled appliances for signs of compromise, not just patch them.

It is worth watching whether watchTowr's technical write-up confirms code execution, and whether Citrix revises its advisory. Public details often lead to wider exploitation, so the window for patching may be short.